Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

2015/07/06

The top three banking malware families

The top three banking malware families

The primary motivator behind banking malware attacks is to capture credentials, financial data, and personal information from employees, and partner company employees, across industries. Then apply this stolen information in fraudulent wire transfers or fake automated clearing house (ACH) transactions to steal funds.


SecurityScorecard sinkholes found 11,952 infections affecting 4,702 organizations and identified the top banking malware families to be Dridex, Bebloh and TinyBanker:
These malware families are simple in functionality which is proving to be more profitable than more complex techniques and methods, such as taking antiquated, bloated code bases from third party malware coders.
Dridex is the most prolific Trojan being circulated within the corporate sector.
The use of banking malware is not limited to large financial institutions, though they remain the primary targets.
Dridex spreading campaigns appear to be orchestrated by more advanced actors with an interest in targeted attacks.
The healthcare industry experienced lowest rate of Bebloh infections, but did not experience the same rate of infection as other industries.
"Security awareness and education is never enough. The evolving tools, techniques, and procedures that are continuously honed by malicious actors make it nearly impossible for every individual in an enterprise to be aware of the latest attack method," said Alex Heid, Chief Research Officer of SecurityScorecard. "To prevent financial losses from an attack, businesses need a closed loop of communication between partners, suppliers, and all third parties that are impacted by banking malware. It is critical that companies think about their collective information security ecosystem when gauging their own security risk."

The top three banking malware families being captured are all direct variants of Zeus, or mimic Zeus-like functionalities. These malware attacks are the preferred method of obtaining stolen credentials, especially when traditional attacks on web applications or network-based attacks are being monitored by internal security teams.


2015/05/19

Every 4 Seconds New Malware Is Born

Every 4 Seconds New Malware Is Born



New research data out today shows that the rate of new malware variants released by malicious attackers continues to break records. According to the G DATA SecurityLabs Malware Report, new malware types were discovered less than every four seconds and 4.1 million new strains were found in the second half of 2014, an increase of close to 125 percent over the first half. Over the course of the entire year, nearly 6 million new malware strains were discovered. This is a 77 percent increase over 2013.
The data shows that in the second half of 2014, Trojans still remained atop the categories tracked by G DATA researchers, but could be on pace to be supplanted by adware. Adware showed the highest rate of growth among all of the malware categories, at a rate of 31.4 percent. While the number of new downloaders was on the rise during the second half, adware's growth rate outpaced that rise to take over the number two spot on the malware category chart. Meanwhile, spyware increased in prevalence while backdoors decreased, putting them in the number four and five spot, respectively.
Interestingly, while rootkits ranked ninth in the categories list, the second half of the year saw a huge spike in their prevalence. The report showed that there were 18 times more new variants than in the first half of 2014.
Specifically within the Trojan market, researchers reported that the second half of the year was novel in that there were no significant innovations compared to previous years.
"In the past, more and more new Trojans have been appearing very quickly in this sector over the years, with new groups in the background using new attack methods. However, in recent months there have been few changes to report," the study said, explaining that in spite of this the volume of attacks is still rising. According to G DATA, the number of banking Trojan attacks rose by 44.5 percent.
The authors speculated that the banking Trojan market seems to have consolidated due to a number of reasons.
"Improved security measures by banks are making it more and more difficult for online bank robbers to get money from bank customers," explains Ralf Benzmüller, head of G DATA SecurityLabs.
Some of the factors at play include an increase of criminal prosecutions against attackers, improved two-factor authentication measures and greater dependence by banks on anomaly detection to reduce fraud. As researchers explained, there's an increased risk for criminals and fraud takes more effort for lower yield. There's also a higher barrier to entry as attacks take "a certain amount of expertise and infrastructure" to carry out.

2015/05/18

High-level, state-sponsored Naikon hackers exposed


The activities of yet another long-running apparently state-sponsored hacking crew have finally been exposed.

The Naikon cyber-espionage group has been targeting government, military and civil organisations around the South China Sea for at least five years, according to researchers at Kaspersky Lab.
The Naikon attackers appear to be Chinese-speaking and chiefly interested in top-level government agencies and civil and military organisations in countries such as the Philippines, Malaysia, Cambodia, Indonesia, Vietnam, Myanmar, Singapore, and Nepal.
The group relies on standard cyber-spy tactics: custom malware and spear phishing featuring emails carrying attachments designed to be of interest to the potential victim. This attachment might look like a Word document, but is in fact an executable file with a double extension.

Naikon has developed platform-independent code and the ability to intercept the entire network traffic, marking them out as more capable than the norm.
The remote access trojan routinely used by the crew comes with 48 commands, including instructions for downloading and uploading data, installing add-on modules or working with the command line.

Each target country has a designated human operator, whose job it is to take advantage of cultural aspects of the country, such as a tendency to use personal email accounts for work.
As well as this social engineering to fine-tune targeting, the group also routinely places its hacking command and control infrastructure (a proxy server) within the country’s borders to facilitate real-time connections and data exfiltration.

The tactic means that suspicious traffic is not travelling outside a target's country and is therefore less likely to be flagged as potentially dodgy and subjected to further scrutiny.
"The criminals behind the Naikon attacks managed to devise a very flexible infrastructure that can be set up in any target country, with information tunnelling from victim systems to the command centre," explained Kurt Baumgartner, principal security researcher at Kaspersky Lab. 
"If the attackers then decide to hunt down another target in another country, they could simply set up a new connection. Having dedicated operators focused on their own particular set of targets also makes things easy for the Naikon espionage group."
The Naikon crew recently locked horns with Hellsing, another cyberspy group. The incident prompted Kaspersky Lab researchers, who were already looking into Hellsing, to cast their attention towards Naikon.

A full write-up of Kaspersky's findings on the Naikon cyberspies can be found in a blog post here.

2014/02/14

The Mask : une nouvelle menace d’Etat ?

Les ingénieurs de Kaspersky Lab ont identifié un virus très sophistiqué qui sévirait depuis 7 ans. Présenté comme une réalisation étatique, il aurait ciblé spécifiquement les agences gouvernementales et représentations diplomatiques de plusieurs pays dont la France.
 
Selon les chercheurs de Kaspersky Lab, le virus The Mask également nommé Careto sévirait depuis 2007 et disposerait de techniques et d’un code de programmation surpassant tous les programmes malveillants « étatiques » découverts jusqu’à maintenant. Selon Kaspersky, ce haut degré de sophistication et sa capacité à rester caché n’est pas normale pour des groupes cybercriminels. Il semble que le virus ait été actif depuis 2007 jusqu’au mois dernier lorsque les serveurs de commande ont été désactivés suite à l’enquête menée par l’éditeur russe. Sa période la plus active aurait été durant l’année 2012. Ses cibles principales auraient été les gouvernements et missions diplomatiques, les entreprises du secteur énergétique, les organismes de recherche, les sociétés de capitaux privés ou encore des militants politiques. 31 pays dont la France auraient été visés. 


Source : Undernews